Professional Documents
Culture Documents
Encor Sa Scenario 2 - Ilm
Encor Sa Scenario 2 - Ilm
Instructor Note: Red font color or gray highlights indicate text that appears in the instructor copy only.
Topology
Addressing Table
R1
G0/0/0.2 10.0.12.1/24 2001:db8:acad:12::1/64 fe80::1:2
R1
G0/0/1.1 10.0.113.1/24 2001:db8:acad:113::1/64 fe80::1:3
R1
G0/0/1.2 10.0.108.1/24 2001:db8:acad:108::1/64 fe80::1:4
R2 G0/0/0.1 10.0.12.2/24 2001:db8:acad:12::2/64 fe80::2:1
R2
G0/0/0.2 10.0.12.2/24 2001:db8:acad:12::2/64 fe80::2:2
R2
G0/0/1.1 10.0.23.2/24 2001:db8:acad:23::2/64 fe80::2:3
R2
G0/0/1.2 10.0.23.2/24 2001:db8:acad:23::2/64 fe80::2:4
R3 G0/0/0.1 10.0.23.3/24 2001:db8:acad:23::3/64 fe80::3:1
R3
G0/0/0.2 10.0.23.3/24 2001:db8:acad:23::3/64 fe80::3:2
R3
G0/0/1.1 10.0.213.1/24 2001:db8:acad:213::1/64 fe80::3:3
R3
G0/0/1.2 10.0.208.1/24 2001:db8:acad:208::1/64 fe80::3:4
2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 1 of 33 www.netacad.com
ENCOR Skills Assessment (Scenario 2)
Objectives
Part 1: Build the Network and Configure Basic Device Settings.
Part 2: Configure VRF and Static Routing
Part 3: Configure L2 Network
Part 4: Configure Security
Part 5: Cleanup
Background / Scenario
In this skills assessment, you are responsible for completing the multi-VRF configuration of the network
supporting “General Users” and “Special Users”. Upon completion, there should be full end-to-end
reachability and the two groups should not be able to communicate with each other. Be sure to verify that
your configurations meet the provided specifications and that the devices perform as required.
Note: The routers used with CCNP hands-on labs are Cisco 4221s with Cisco IOS XE Release 16.9.4
(universalk9 image). The switches used in the labs are Cisco Catalyst 3650s with Cisco IOS XE Release
16.9.4 (universalk9 image) and Cisco Catalyst 2960s with Cisco IOS Release 15.2(2) (lanbasek9 image).
Other routers, switches, and Cisco IOS versions can be used. Depending on the model and Cisco IOS
version, the commands available and the output produced might vary from what is shown in the labs.
Note: Make sure that the switches have been erased and have no startup configurations. If you are unsure,
contact your instructor.
Note: The default Switch Database Manager (SDM) template on a Catalyst 2960 does not support IPv6. You
must change the default SDM template to the dual-ipv4-and-ipv6 default template using the sdm prefer dual-
ipv4-and-ipv6 default global configuration command. Changing the template will require a reboot.
Instructor Note: Refer to the Instructor Lab Manual for the procedures to initialize and reload devices.
Instructor Note: This skills assessment presumes that Part 1: Build the Network and Configure Basic Device
Settings and Interface Addressing is not a graded or timed component of the exercise.
Instructor Note: In the interest of time, it may be appropriate to modify some of the requirements from “all
devices” to a select device.
Required Resources
3 Routers (Cisco 4221 with Cisco IOS XE Release 16.9.4 universal image or comparable)
2 Switches (Cisco 3650 with Cisco IOS XE release 16.9.4 universal image or comparable)
1 Switch (Cisco 2960 with Cisco IOS release 15.2 lanbase image or comparable)
4 PCs (Choice of operating system with a terminal emulation program)
Console cables to configure the Cisco IOS devices via the console ports
Ethernet cables as shown in the topology
2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 2 of 33 www.netacad.com
ENCOR Skills Assessment (Scenario 2)
Instructions
Part 1: Build the Network and Configure Basic Device Settings and Interface
Addressing
In Part 1, you will set up the network topology and configure basic settings.
2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 3 of 33 www.netacad.com
ENCOR Skills Assessment (Scenario 2)
2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 4 of 33 www.netacad.com
ENCOR Skills Assessment (Scenario 2)
On R1, R2, and R3, configure IPv4 and All routers will use Router-On-A-Stick on their
IPv6 interfaces on each VRF as G0/0/1.x interfaces to support separation of the
detailed in the addressing table above. VRFs.
Sub-interface 1:
In the Special Users VRF
Use dot1q encapsulation 13
2.2 IPv4 and IPv6 GUA and link-local addresses 12
Enable the interfaces
Sub-interface 2:
In the General Users VRF
Use dot1q encapsulation 8
IPv4 and IPv6 GUA and link-local addresses
Enable the interfaces
On R1 and R3, configure default static Configure VRF static routes for both IPv4 and
2.3 8
routes pointing to R2. IPv6 in both VRFs.
2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 5 of 33 www.netacad.com
ENCOR Skills Assessment (Scenario 2)
Verify IPv4 and IPv6 pings of R3 from R1; all pings should be successful. (Task 2.4)
R1# ping vrf General-Users 10.0.208.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.0.208.1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 6 of 33 www.netacad.com
ENCOR Skills Assessment (Scenario 2)
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/2 ms
On D1, D2, and A1, disable all On D1 and D2, shutdown G1/0/1 to G1/0/24.
3.1 interfaces. 2
On A1, shutdown F0/1 – F0/24, G0/1 – G0/2.
On D1 and D2, configure the trunk Configure and enable the G1/0/11 link as a trunk
3.2 4
links to R1 and R3. link.
On D1 and A1, configure the On D1, configure and enable:
EtherChannel. Interface G1/0/5 and G1/0/6
Port Channel 1 using PAgP
3.3 8
On A1, configure enable:
Interface F0/1 and F0/2
Port Channel 1 using PAgP
On D1, D2, and A1, configure access Configure and enable the access ports as follows:
ports for PC1, PC2, PC3, and PC4. On D1, configure interface G1/0/23 as an
access port in VLAN 13 and enable Portfast.
On D2, configure interface G1/0/23 as an
3.4 access port in VLAN 13 and enable Portfast. 6
On D2, configure interface G1/0/24 as an
access port in VLAN 8 and enable Portfast.
On A1, configure interface F0/23 as an access
port in VLAN 8 and enable Portfast.
2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 7 of 33 www.netacad.com
ENCOR Skills Assessment (Scenario 2)
Issue the command show etherchannel summary to verify the etherchannel settings.
D1# show etherchannel summary
Flags: D - down P - bundled in port-channel
I - stand-alone s - suspended
H - Hot-standby (LACP only)
R - Layer3 S - Layer2
U - in use f - failed to allocate aggregator
Issue the command show run interface g1/0/23 or show run interface f0/23 to validate host port settings.
D1# show run interface g1/0/23
Building configuration...
Verify that PC1 can reach PC2. IPv4 and IPv6 pings from PC1 to PC2 are successful.
Verify that PC3 can reach PC4. IPv4 and IPv6 pings from PC3 to PC4 are successful.
Note: PC1 and PC2 cannot ping PC3 or PC4.
2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 8 of 33 www.netacad.com
ENCOR Skills Assessment (Scenario 2)
On all devices, enable AAA and enable Enable AAA authentication using the local
5.3 2
AAA authentication. database on all lines.
Instructor Verification:
Issue the command show run | include aaa|username to verify that the AAA settings are configured.
D2# show run | include aaa|username
aaa new-model
aaa authentication login default local
aaa session-id common
username admin privilege 15 secret 9
$9$XjgowiPNCh.RRk$CwCEW/a6DqO12aRmLFaBfhhJPW.V/7KuJaqHS5m4RmU
Part 5: Cleanup
NOTE: DO NOT PROCEED WITH CLEANUP UNTIL YOUR INSTRUCTOR HAS GRADED YOUR SKILLS
ASSESSMENT AND HAS INFORMED YOU THAT YOU MAY BEGIN CLEANUP.
Unless directed otherwise by the instructor, restore host computer network connectivity, and then turn off
power to the host computers.
Remove NVRAM configuration files (if saved) and vlan databases from all devices before turning them off or
reloading them.
End of document
Router R1
vrf definition General-Users
address-family ipv4
address-family ipv6
exit
vrf definition Special-Users
2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 9 of 33 www.netacad.com
ENCOR Skills Assessment (Scenario 2)
address-family ipv4
address-family ipv6
exit
interface g0/0/0.1
encapsulation dot1q 13
vrf forwarding Special-Users
ip address 10.0.12.1 255.255.255.0
ipv6 address fe80::1:1 link-local
ipv6 address 2001:db8:acad:12::1/64
no shutdown
exit
interface g0/0/0.2
encapsulation dot1q 8
vrf forwarding General-Users
ip address 10.0.12.1 255.255.255.0
ipv6 address fe80::1:2 link-local
ipv6 address 2001:db8:acad:12::1/64
no shutdown
exit
interface g0/0/0
no ip address
no shutdown
exit
interface g0/0/1.1
encapsulation dot1q 13
vrf forwarding Special-Users
ip address 10.0.113.1 255.255.255.0
ipv6 address fe80::1:3 link-local
ipv6 address 2001:db8:acad:113::1/64
no shutdown
exit
interface g0/0/1.2
encapsulation dot1q 8
vrf forward General-Users
ip address 10.0.108.1 255.255.255.0
ipv6 address fe80::1:4 link-local
ipv6 address 2001:db8:acad:108::1/64
no shutdown
exit
interface g0/0/1
no ip address
no shutdown
exit
ip route vrf Special-Users 0.0.0.0 0.0.0.0 10.0.12.2
ip route vrf General-Users 0.0.0.0 0.0.0.0 10.0.12.2
ipv6 route vrf Special-Users ::/0 2001:db8:acad:12::2
ipv6 route vrf General-Users ::/0 2001:db8:acad:12::2
end
2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 10 of 33 www.netacad.com
ENCOR Skills Assessment (Scenario 2)
Router R2
vrf definition General-Users
address-family ipv4
address-family ipv6
exit
vrf definition Special-Users
address-family ipv4
address-family ipv6
exit
interface g0/0/0.1
encapsulation dot1q 13
vrf forwarding Special-Users
ip address 10.0.12.2 255.255.255.0
ipv6 address fe80::2:1 link-local
ipv6 address 2001:db8:acad:12::2/64
no shutdown
exit
interface g0/0/0.2
encapsulation dot1q 8
vrf forwarding General-Users
ip address 10.0.12.2 255.255.255.0
ipv6 address fe80::2:2 link-local
ipv6 address 2001:db8:acad:12::2/64
no shutdown
exit
interface g0/0/0
no ip address
no shutdown
exit
interface g0/0/1.1
encapsulation dot1q 13
vrf forwarding Special-Users
ip address 10.0.23.2 255.255.255.0
ipv6 address fe80::2:3 link-local
ipv6 address 2001:db8:acad:23::2/64
no shutdown
exit
interface g0/0/1.2
encapsulation dot1q 8
vrf forwarding General-Users
ip address 10.0.23.2 255.255.255.0
ipv6 address fe80::2:4 link-local
ipv6 address 2001:db8:acad:23::2/64
no shutdown
exit
interface g0/0/1
no ip address
no shutdown
exit
ip route vrf Special-Users 10.0.113.0 255.255.255.0 10.0.12.1
2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 11 of 33 www.netacad.com
ENCOR Skills Assessment (Scenario 2)
Router R3
vrf definition General-Users
address-family ipv4
address-family ipv6
exit
vrf definition Special-Users
address-family ipv4
address-family ipv6
exit
interface g0/0/0.1
encapsulation dot1q 13
vrf forwarding Special-Users
ip address 10.0.23.3 255.255.255.0
ipv6 address fe80::3:1 link-local
ipv6 address 2001:db8:acad:23::3/64
no shutdown
exit
interface g0/0/0.2
encapsulation dot1q 8
vrf forwarding General-Users
ip address 10.0.23.3 255.255.255.0
ipv6 address fe80::3:2 link-local
ipv6 address 2001:db8:acad:23::3/64
no shutdown
exit
interface g0/0/0
no ip address
no shutdown
exit
interface g0/0/1.1
encapsulation dot1q 13
vrf forwarding Special-Users
ip address 10.0.213.1 255.255.255.0
ipv6 address fe80::3:3 link-local
ipv6 address 2001:db8:acad:213::1/64
no shutdown
exit
interface g0/0/1.2
encapsulation dot1q 8
vrf forward General-Users
ip address 10.0.208.1 255.255.255.0
2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 12 of 33 www.netacad.com
ENCOR Skills Assessment (Scenario 2)
Switch D1
interface range g1/0/1-24
shutdown
exit
interface g1/0/11
switchport mode trunk
no shutdown
exit
!
interface g1/0/23
switchport mode access
switchport access vlan 13
spanning-tree portfast
no shutdown
exit
interface range g1/0/5-6
switchport mode trunk
channel-group 1 mode desirable
no shutdown
exit
Switch D2
interface range g1/0/1-24
shutdown
exit
interface g1/0/11
switchport mode trunk
no shutdown
exit
!
interface g1/0/23
switchport mode access
switchport access vlan 13
spanning-tree portfast
2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 13 of 33 www.netacad.com
ENCOR Skills Assessment (Scenario 2)
no shutdown
exit
interface g1/0/24
switchport mode access
switchport access vlan 8
spanning-tree portfast
no shutdown
exit
Switch A1
interface range f0/1-24, g0/1-2
shutdown
exit
interface f0/23
switchport mode access
switchport access vlan 8
spanning-tree portfast
no shutdown
exit
interface range f0/1-2
switchport mode trunk
channel-group 1 mode desirable
no shutdown
exit
Router R1
R1# show run
Building configuration...
2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 14 of 33 www.netacad.com
ENCOR Skills Assessment (Scenario 2)
hostname R1
!
boot-start-marker
boot-end-marker
!
!
vrf definition General-Users
!
address-family ipv4
exit-address-family
!
address-family ipv6
exit-address-family
!
vrf definition Special-Users
!
address-family ipv4
exit-address-family
!
address-family ipv6
exit-address-family
!
enable secret 9 $9$zoLy2xVn9zcnb.$CFCHOBcQkjBm2C8a7VzDkhM2DCYnF9/aSc4B/FRXO2k
!
aaa new-model
!
aaa authentication login default local
!
aaa session-id common
!
no ip domain lookup
!
login on-success log
!
subscriber templating
!
ipv6 unicast-routing
multilink bundle-name authenticated
!
spanning-tree extend system-id
!
username admin privilege 15 secret 9
$9$5N85J1uzgRjVpE$z4mPVfXwPae5qgqpwIC6UgVMGb8Ryf1h9oNg79qhLDc
!
redundancy
mode none
!
interface GigabitEthernet0/0/0
no ip address
negotiation auto
2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 15 of 33 www.netacad.com
ENCOR Skills Assessment (Scenario 2)
!
interface GigabitEthernet0/0/0.1
encapsulation dot1Q 13
vrf forwarding Special-Users
ip address 10.0.12.1 255.255.255.0
ipv6 address FE80::1:1 link-local
ipv6 address 2001:DB8:ACAD:12::1/64
!
interface GigabitEthernet0/0/0.2
encapsulation dot1Q 8
vrf forwarding General-Users
ip address 10.0.12.1 255.255.255.0
ipv6 address FE80::1:2 link-local
ipv6 address 2001:DB8:ACAD:12::1/64
!
interface GigabitEthernet0/0/1
no ip address
negotiation auto
!
interface GigabitEthernet0/0/1.1
encapsulation dot1Q 13
vrf forwarding Special-Users
ip address 10.0.113.1 255.255.255.0
ipv6 address FE80::1:3 link-local
ipv6 address 2001:DB8:ACAD:113::1/64
!
interface GigabitEthernet0/0/1.2
encapsulation dot1Q 8
vrf forwarding General-Users
ip address 10.0.108.1 255.255.255.0
ipv6 address FE80::1:4 link-local
ipv6 address 2001:DB8:ACAD:108::1/64
!
interface Serial0/1/0
no ip address
!
interface Serial0/1/1
no ip address
!
ip forward-protocol nd
no ip http server
ip http secure-server
ip route vrf General-Users 0.0.0.0 0.0.0.0 10.0.12.2
ip route vrf Special-Users 0.0.0.0 0.0.0.0 10.0.12.2
!
ipv6 route vrf General-Users ::/0 2001:DB8:ACAD:12::2
ipv6 route vrf Special-Users ::/0 2001:DB8:ACAD:12::2
!
control-plane
!
2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 16 of 33 www.netacad.com
ENCOR Skills Assessment (Scenario 2)
Router R2
R2# show run
Building configuration...
2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 17 of 33 www.netacad.com
ENCOR Skills Assessment (Scenario 2)
!
aaa new-model
!
aaa authentication login default local
!
aaa session-id common
!
no ip domain lookup
!
login on-success log
!
subscriber templating
!
ipv6 unicast-routing
multilink bundle-name authenticated
!
spanning-tree extend system-id
!
username admin privilege 15 secret 9
$9$5N85J1uzgRjVpE$z4mPVfXwPae5qgqpwIC6UgVMGb8Ryf1h9oNg79qhLDc
!
redundancy
mode none
!
interface GigabitEthernet0/0/0
no ip address
negotiation auto
!
interface GigabitEthernet0/0/0.1
encapsulation dot1Q 13
vrf forwarding Special-Users
ip address 10.0.12.2 255.255.255.0
ipv6 address FE80::2:1 link-local
ipv6 address 2001:DB8:ACAD:12::2/64
!
interface GigabitEthernet0/0/0.2
encapsulation dot1Q 8
vrf forwarding General-Users
ip address 10.0.12.2 255.255.255.0
ipv6 address FE80::2:2 link-local
ipv6 address 2001:DB8:ACAD:12::2/64
!
interface GigabitEthernet0/0/1
no ip address
negotiation auto
!
interface GigabitEthernet0/0/1.1
encapsulation dot1Q 13
vrf forwarding Special-Users
ip address 10.0.23.2 255.255.255.0
2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 18 of 33 www.netacad.com
ENCOR Skills Assessment (Scenario 2)
Router R3
R3# show run
Building configuration...
2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 19 of 33 www.netacad.com
ENCOR Skills Assessment (Scenario 2)
2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 20 of 33 www.netacad.com
ENCOR Skills Assessment (Scenario 2)
negotiation auto
!
interface GigabitEthernet0/0/0.1
encapsulation dot1Q 13
vrf forwarding Special-Users
ip address 10.0.23.3 255.255.255.0
ipv6 address FE80::3:1 link-local
ipv6 address 2001:DB8:ACAD:23::3/64
!
interface GigabitEthernet0/0/0.2
encapsulation dot1Q 8
vrf forwarding General-Users
ip address 10.0.23.3 255.255.255.0
ipv6 address FE80::3:2 link-local
ipv6 address 2001:DB8:ACAD:23::3/64
!
interface GigabitEthernet0/0/1
no ip address
negotiation auto
!
interface GigabitEthernet0/0/1.1
encapsulation dot1Q 13
vrf forwarding Special-Users
ip address 10.0.213.1 255.255.255.0
ipv6 address FE80::3:3 link-local
ipv6 address 2001:DB8:ACAD:213::1/64
!
interface GigabitEthernet0/0/1.2
encapsulation dot1Q 8
vrf forwarding General-Users
ip address 10.0.208.1 255.255.255.0
ipv6 address FE80::3:4 link-local
ipv6 address 2001:DB8:ACAD:208::1/64
!
interface Serial0/1/0
no ip address
!
interface Serial0/1/1
no ip address
!
ip forward-protocol nd
no ip http server
ip http secure-server
ip route vrf General-Users 0.0.0.0 0.0.0.0 10.0.23.2
ip route vrf Special-Users 0.0.0.0 0.0.0.0 10.0.23.2
!
ipv6 route vrf General-Users ::/0 2001:DB8:ACAD:23::2
ipv6 route vrf Special-Users ::/0 2001:DB8:ACAD:23::2
!
control-plane
2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 21 of 33 www.netacad.com
ENCOR Skills Assessment (Scenario 2)
!
banner motd ^C R3, ENCOR Skills Assessment, Scenario 2 ^C
!
line con 0
exec-timeout 0 0
logging synchronous
transport input none
stopbits 1
line aux 0
stopbits 1
line vty 0 4
login
!
end
Switch D1
D1# show run
Building configuration...
2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 22 of 33 www.netacad.com
ENCOR Skills Assessment (Scenario 2)
no ip domain lookup
!
login on-success log
ipv6 unicast-routing
!
license boot level ipservicesk9
!
diagnostic bootup level minimal
!
spanning-tree mode rapid-pvst
spanning-tree extend system-id
!
username admin privilege 15 secret 9
$9$x8R/b5GOdIKyqU$ewYxQctKHyXyOSHvPXM6.WvzvhfrIkCoxPygXDmyTxQ
!
redundancy
mode sso
!
transceiver type all
monitoring
!
class-map match-any system-cpp-police-topology-control
description Topology control
class-map match-any system-cpp-police-sw-forward
description Sw forwarding, L2 LVX data, LOGGING
class-map match-any system-cpp-default
description Inter FED, EWLC control, EWLC data
class-map match-any system-cpp-police-sys-data
description Learning cache ovfl, High Rate App, Exception, EGR Exception,
NFLSAMPLED DATA, RPF Failed
class-map match-any system-cpp-police-punt-webauth
description Punt Webauth
class-map match-any system-cpp-police-l2lvx-control
description L2 LVX control packets
class-map match-any system-cpp-police-forus
description Forus Address resolution and Forus traffic
class-map match-any system-cpp-police-multicast-end-station
description MCAST END STATION
class-map match-any system-cpp-police-multicast
description Transit Traffic and MCAST Data
class-map match-any system-cpp-police-l2-control
description L2 control
class-map match-any system-cpp-police-dot1x-auth
description DOT1X Auth
class-map match-any system-cpp-police-data
description ICMP redirect, ICMP_GEN and BROADCAST
class-map match-any system-cpp-police-stackwise-virt-control
description Stackwise Virtual
class-map match-any non-client-nrt-class
class-map match-any system-cpp-police-routing-control
2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 23 of 33 www.netacad.com
ENCOR Skills Assessment (Scenario 2)
2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 24 of 33 www.netacad.com
ENCOR Skills Assessment (Scenario 2)
interface GigabitEthernet1/0/11
switchport mode trunk
!
interface GigabitEthernet1/0/12
shutdown
!
interface GigabitEthernet1/0/13
shutdown
!
interface GigabitEthernet1/0/14
shutdown
!
interface GigabitEthernet1/0/15
shutdown
!
interface GigabitEthernet1/0/16
shutdown
!
interface GigabitEthernet1/0/17
shutdown
!
interface GigabitEthernet1/0/18
shutdown
!
interface GigabitEthernet1/0/19
shutdown
!
interface GigabitEthernet1/0/20
shutdown
!
interface GigabitEthernet1/0/21
shutdown
!
interface GigabitEthernet1/0/22
shutdown
!
interface GigabitEthernet1/0/23
switchport access vlan 13
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet1/0/24
shutdown
!
interface GigabitEthernet1/1/1
!
interface GigabitEthernet1/1/2
!
interface GigabitEthernet1/1/3
!
2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 25 of 33 www.netacad.com
ENCOR Skills Assessment (Scenario 2)
interface GigabitEthernet1/1/4
!
interface Vlan1
no ip address
!
ip forward-protocol nd
ip http server
ip http secure-server
!
control-plane
service-policy input system-cpp-policy
!
banner motd ^C D1, ENCOR Skills Assessment, Scenario 2 ^C
!
line con 0
exec-timeout 0 0
logging synchronous
stopbits 1
line aux 0
stopbits 1
line vty 0 4
login
line vty 5 15
login
!
end
Switch D2
D2# show run
Building configuration...
2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 26 of 33 www.netacad.com
ENCOR Skills Assessment (Scenario 2)
exit-address-family
!
enable secret 9 $9$wOqJe6W8Yasi9k$7Mq8sTne4AGIivudnv6v4G.e30OcRAuXoSGcAa0DohY
!
aaa new-model
!
aaa authentication login default local
!
aaa session-id common
switch 1 provision ws-c3650-24ps
!
ip routing
!
no ip domain lookup
!
login on-success log
ipv6 unicast-routing
!
license boot level ipservicesk9!
!
diagnostic bootup level minimal
!
spanning-tree mode rapid-pvst
spanning-tree extend system-id
!
username admin privilege 15 secret 9
$9$1q0osHH4lstBHU$1DhwuWo4f1j.rLppTRRsOB86WpZaJIHSeukQ1a4uPA6
!
redundancy
mode sso
!
transceiver type all
monitoring
!
class-map match-any system-cpp-police-topology-control
description Topology control
class-map match-any system-cpp-police-sw-forward
description Sw forwarding, L2 LVX data, LOGGING
class-map match-any system-cpp-default
description Inter FED, EWLC control, EWLC data
class-map match-any system-cpp-police-sys-data
description Learning cache ovfl, High Rate App, Exception, EGR Exception,
NFLSAMPLED DATA, RPF Failed
class-map match-any system-cpp-police-punt-webauth
description Punt Webauth
class-map match-any system-cpp-police-l2lvx-control
description L2 LVX control packets
class-map match-any system-cpp-police-forus
description Forus Address resolution and Forus traffic
class-map match-any system-cpp-police-multicast-end-station
2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 27 of 33 www.netacad.com
ENCOR Skills Assessment (Scenario 2)
2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 28 of 33 www.netacad.com
ENCOR Skills Assessment (Scenario 2)
shutdown
!
interface GigabitEthernet1/0/9
shutdown
!
interface GigabitEthernet1/0/10
shutdown
!
interface GigabitEthernet1/0/11
switchport mode trunk
!
interface GigabitEthernet1/0/12
shutdown
!
interface GigabitEthernet1/0/13
shutdown
!
interface GigabitEthernet1/0/14
shutdown
!
interface GigabitEthernet1/0/15
shutdown
!
interface GigabitEthernet1/0/16
shutdown
!
interface GigabitEthernet1/0/17
shutdown
!
interface GigabitEthernet1/0/18
shutdown
!
interface GigabitEthernet1/0/19
shutdown
!
interface GigabitEthernet1/0/20
shutdown
!
interface GigabitEthernet1/0/21
shutdown
!
interface GigabitEthernet1/0/22
shutdown
!
interface GigabitEthernet1/0/23
switchport access vlan 13
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet1/0/24
2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 29 of 33 www.netacad.com
ENCOR Skills Assessment (Scenario 2)
Switch A1
A1# show run
Building configuration...
2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 30 of 33 www.netacad.com
ENCOR Skills Assessment (Scenario 2)
!
boot-start-marker
boot-end-marker
!
enable secret 9 $9$a7qnivVydjhJqa$ehWSSxHj7jf6s7gjbuVc4PLGJY0dv2k.VtPqL1cn0vs
!
username admin privilege 15 secret 9
$9$itvXO10OdR7sMq$9ffgjFDlEL2j8T3040Eb21fA/2Cyjb2tHF5rZrWtZKY
aaa new-model
!
aaa authentication login default local
!
aaa session-id common
system mtu routing 1500
!
no ip domain-lookup
ipv6 unicast-routing
!
spanning-tree mode rapid-pvst
spanning-tree extend system-id
!
vlan internal allocation policy ascending
!
interface Port-channel1
switchport mode trunk
!
interface FastEthernet0/1
switchport mode trunk
channel-group 1 mode desirable
!
interface FastEthernet0/2
switchport mode trunk
channel-group 1 mode desirable
!
interface FastEthernet0/3
shutdown
!
interface FastEthernet0/4
shutdown
!
interface FastEthernet0/5
shutdown
!
interface FastEthernet0/6
shutdown
!
interface FastEthernet0/7
shutdown
!
interface FastEthernet0/8
2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 31 of 33 www.netacad.com
ENCOR Skills Assessment (Scenario 2)
shutdown
!
interface FastEthernet0/9
shutdown
!
interface FastEthernet0/10
shutdown
!
interface FastEthernet0/11
shutdown
!
interface FastEthernet0/12
shutdown
!
interface FastEthernet0/13
shutdown
!
interface FastEthernet0/14
shutdown
!
interface FastEthernet0/15
shutdown
!
interface FastEthernet0/16
shutdown
!
interface FastEthernet0/17
shutdown
!
interface FastEthernet0/18
shutdown
!
interface FastEthernet0/19
shutdown
!
interface FastEthernet0/20
shutdown
!
interface FastEthernet0/21
shutdown
!
interface FastEthernet0/22
shutdown
!
interface FastEthernet0/23
switchport access vlan 8
switchport mode access
spanning-tree portfast edge
!
interface FastEthernet0/24
2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 32 of 33 www.netacad.com
ENCOR Skills Assessment (Scenario 2)
shutdown
!
interface GigabitEthernet0/1
shutdown
!
interface GigabitEthernet0/2
shutdown
!
interface Vlan1
no ip address
!
ip http server
ip http secure-server
!
banner motd ^C A1, ENCOR Skills Assessment, Scenario 2 ^C
!
line con 0
exec-timeout 0 0
logging synchronous
line vty 0 4
login
line vty 5 15
login
!
end
2020 - 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 33 of 33 www.netacad.com